Register of Processing Activities (ROPA)

Version 2026-06-19-v3-es. Last reviewed 19 June 2026.

Article 30 GDPR requires the controller to maintain a register of every processing activity. The AEPD expects this register to be available on request; we publish the customer-facing summary here. The internal version, including the names of staff with access and the technical and organisational security measures, is held by the Data Protection Officer and can be inspected on lawful demand by the AEPD.

Controller

NEMRAC Consulting S.L. (T4G Impact), Spain TIN B44624740, Spain. Sole controller; no joint-controllership. Data Protection Officer: dpo@t4glab.com.

Processing activities

ActivityCategories of dataLawful basisRecipients / sub-processorsTransfers outside EEARetention
Account creation and authenticationEmail, full name, password hash, federated IDsArt. 6(1)(b) GDPR — performance of a contractAmazon Cognito (AWS EMEA SARL)None — processed in eu-west-124 months from last sign-in, then delete or anonymise
Roster profileSectors, fields, salary expectations, availability, notesArt. 6(1)(a) — consent (visibility on the roster)Internal admins; AWS DynamoDBNoneTogether with the account
CV storageCV document, frequently including Art. 9 GDPR special-category data (health, religion, ethnicity, union, sexual orientation)Art. 6(1)(b) for the file; Art. 9(2)(a) explicit consent for any Art. 9 contentAWS S3 (EU-encrypted with KMS)NoneActive candidate: 12 months from upload with annual re-consent. Unsuccessful candidate: 12 months from rejection. Withdrawn: 30 days max. See privacy §6.
AI-assisted CV parsingCV file → structured enrichment fieldsArt. 6(1)(f) — legitimate interest in a usable roster; Art. 9(2)(a) for any special-category contentAnthropic PBC (Claude Sonnet 4.6)United States (Anthropic). EU–US Data Privacy Framework; fallback SCC + TIATied to the source CV — deleted with it
Federated sign-inEmail and federated subject identifier from GoogleArt. 6(1)(b) — performance of contractGoogle LLCUnited States. EU–US Data Privacy Framework + Google Model ClausesTogether with the account
Marketing communicationsEmail, opt-in flag, opt-in timestampArt. 6(1)(a) GDPR + Art. 21 LSSI (Spain)Internal adminsNoneWhile opted in; deleted within 30 days of withdrawal
Consent audit (Art. 7 GDPR)Profile id, email, consent kind, action, timestamp, policy versionArt. 6(1)(c) + Art. 7(1) — proof obligationInternal admins; AWS DynamoDBNone6 years from the event under Art. 17(3)(e) (defence of legal claims); survives erasure of the underlying profile
Admin review audit (CvAccessLog)Profile id, admin email, action, timestampArt. 6(1)(c); EU AI Act Art. 26(6) deployer log-retention dutyInternal adminsNone6 months minimum
Security and abuse preventionIP, user-agent, request path, error logsArt. 6(1)(f) — legitimate interest in service integrityAWS CloudWatch (EU)None90 days

Special-category data (Art. 9 GDPR)

We do not intentionally collect Art. 9 data. We acknowledge that CVs frequently include such content. We rely on the explicit consent of the candidate (Art. 9(2)(a)) given at the point of upload, with the right to refuse without losing access to the Service.

Children

The Service is for adults 18+. We do not process the personal data of minors. Spain’s LOPDGDD Art. 7 sets the digital-consent age at 14, which is lower than the GDPR default of 16 — we do not rely on the LOPDGDD lower threshold and instead apply a strict 18+ floor.

Security measures (summary)

  • TLS in transit; AWS KMS encryption at rest.
  • Row-level authorisation: candidates can only read their own row; admins are gated by a Cognito ADMIN group with mandatory MFA.
  • Every admin action against a candidate’s data is recorded in CvAccessLog.
  • Anthropic transfer additionally covered by an internal Transfer Impact Assessment, reviewed at least annually.
  • Restricted profiles (Art. 18 GDPR) are excluded at code level from matching and from enrichment reruns.

Contact

DPO: dpo@t4glab.com.
Privacy enquiries: privacy@t4glab.com.
Lead supervisory authority: AEPD.